An empirical study of privacy labels on the Apple iOS mobile app store

Gian Luca Scoccia, Marco Autili, G. Stilo, P. Inverardi
{"title":"An empirical study of privacy labels on the Apple iOS mobile app store","authors":"Gian Luca Scoccia, Marco Autili, G. Stilo, P. Inverardi","doi":"10.1145/3524613.3527813","DOIUrl":null,"url":null,"abstract":"Privacy labels provide an easy and recognizable overview of data collection practices adopted by mobile apps developers. Specifically, on the Apple App Store, privacy labels are displayed on each mobile app's page and summarize what data is collected by the app, how it is used, and for what purposes it is needed. Starting from the release of iOS version 14.3 developers are required to provide privacy labels for their applications. We conducted a large-scale empirical study, collecting and analyzing the privacy labels of 17, 312 apps published on the App Store, to understand and characterize how sensitive data is collected and shared. The results of our analysis highlight important criticalities about the collection and sharing of personal data for tracking purposes. In particular, on average free applications collect more sensitive data, the majority of data is collected in an unanonimyzed form, and a wide range of sensitive information are collected for tracking purposes. The analysis provides also evidence to support the decision-making of users, platform maintainers, and regulators. Furthermore, we repeated the data collection and analysis after seven months, following the introduction of additional run-time tracking controls by Apple. Comparing the two datasets, we observed that the newly introduced measures resulted in a statistically significant decrease in the number of apps that collect data for tracking purposes. At the same time, we observed a growth in overall data collection.","PeriodicalId":408284,"journal":{"name":"2022 IEEE/ACM 9th International Conference on Mobile Software Engineering and Systems (MobileSoft)","volume":"33 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-05-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"8","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE/ACM 9th International Conference on Mobile Software Engineering and Systems (MobileSoft)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3524613.3527813","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 8

Abstract

Privacy labels provide an easy and recognizable overview of data collection practices adopted by mobile apps developers. Specifically, on the Apple App Store, privacy labels are displayed on each mobile app's page and summarize what data is collected by the app, how it is used, and for what purposes it is needed. Starting from the release of iOS version 14.3 developers are required to provide privacy labels for their applications. We conducted a large-scale empirical study, collecting and analyzing the privacy labels of 17, 312 apps published on the App Store, to understand and characterize how sensitive data is collected and shared. The results of our analysis highlight important criticalities about the collection and sharing of personal data for tracking purposes. In particular, on average free applications collect more sensitive data, the majority of data is collected in an unanonimyzed form, and a wide range of sensitive information are collected for tracking purposes. The analysis provides also evidence to support the decision-making of users, platform maintainers, and regulators. Furthermore, we repeated the data collection and analysis after seven months, following the introduction of additional run-time tracking controls by Apple. Comparing the two datasets, we observed that the newly introduced measures resulted in a statistically significant decrease in the number of apps that collect data for tracking purposes. At the same time, we observed a growth in overall data collection.
苹果iOS手机应用商店隐私标签的实证研究
隐私标签提供了移动应用程序开发人员采用的数据收集实践的简单和可识别的概述。具体来说,在苹果应用商店,隐私标签显示在每个移动应用程序的页面上,并总结了应用程序收集了哪些数据,如何使用这些数据,以及需要这些数据的目的。从iOS 14.3版本发布开始,开发者需要为他们的应用程序提供隐私标签。我们进行了大规模的实证研究,收集并分析了App Store上发布的17,312个应用的隐私标签,以了解和描述敏感数据是如何被收集和共享的。我们的分析结果强调了为跟踪目的而收集和共享个人数据的重要关键。特别是,平均而言,免费应用程序收集了更多的敏感数据,大多数数据是以未匿名的形式收集的,并且为了跟踪目的而收集了大量敏感信息。分析还为支持用户、平台维护人员和监管机构的决策提供了证据。此外,在苹果引入额外的运行时跟踪控制后,我们在7个月后重复了数据收集和分析。比较这两个数据集,我们观察到,新引入的措施导致为跟踪目的收集数据的应用程序数量在统计上显著减少。与此同时,我们观察到整体数据收集的增长。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信